background image

INS_CWGE28FX4TX24MS_REV–   08/31/12     PAGE 3

INSTALLATION AND OPERATION MANUAL 

CWGE28FX4TX24MS

TECH SUPPORT: 1.888.678.9427

About This Guide

This guide is intended for different users such as engineers, integrators, developers, IT managers, 
and technicians. 
It assumes that users have some PC competence and are familiar with Microsoft Windows 
operating systems and web browsers such as Windows Internet Explorer and Mozilla Firefox, as 
well as have knowledge of the following:

 

»

Installation of electronic equipment

 

»

Electrical regulations and guidelines

 

»

Knowledge of Local Area Network technology

Related Documentation

The following documentation is also available:

 

»

CWGE28FX4TX24MS Datasheet

About ComNet

ComNet develops and markets the next generation of video solutions for the CCTV, defense, and 
homeland security markets. At the core of ComNet’s solutions are a variety of high-end video 
servers and the ComNet IVS software, which provide the industry with a standard platform for 
analytics and security management systems enabling leading performance, compact and cost 
effective solutions.
ComNet’s products are available in commercial and rugged form.

Website

For information on ComNet’s entire product line, please visit the ComNet website at  

http://www.comnet.net

Support

For any questions or technical assistance, please contact your sales person (

[email protected]

) or 

the customer service support center (

[email protected]

)

Safety

 

»

 Only ComNet service personnel can service the equipment. Please contact ComNet Technical 
Support.

 

»

 The equipment should be installed in locations with controlled access, or other means of 
security, and controlled by persons of authority.

Summary of Contents for CWGE28FX4TX24MS

Page 1: ...s are SFP configurable for fiber type multimode or single mode connector type and distance The exclusive C Ring redundant ring feature protects networks from interruptions or temporary malfunctions wi...

Page 2: ...3 Safety 3 Overview 4 Introduction 4 Software Features 5 Hardware Features 6 Hardware Installation 7 Rear Panel 8 Rack mount kit assembly 8 Cables 10 Ethernet Cables 10 SFP Small Form Factor Pluggable...

Page 3: ...xt generation of video solutions for the CCTV defense and homeland security markets At the core of ComNet s solutions are a variety of high end video servers and the ComNet IVS software which provide...

Page 4: ...idth ComNet s Ethernet switches also support application based QoS Application based QoS can set the highest priority for data stream according to TCP UDP port number The ComNet special IP police func...

Page 5: ...Management Event notification by Email and SNMP trap Windows Utility eConsole Web based Telnet and Console CLI configuration Enable disable ports MAC based port security Port based network access con...

Page 6: ...tures One 100 240VAC power input Operating Temperature 10 to 60 C 14 to 140 F Storage Temperature 40 to 85 C 40 to 185 F Operating Humidity 5 to 95 non condensing Casing IP 20 24 x 10 100 1000Base T X...

Page 7: ...1000Base X Fiber port on SFP port 4 LED for Ethernet ports Link Act status Left Green for 1000Mbps indicator Amber for 10 100Mbps indicator 5 LED for Ethernet ports Duplex status 6 LED for SFP ports...

Page 8: ...TECH SUPPORT 1 888 678 9427 Rear Panel 1 2 CWGE28FX4TX24MS Rear Panel 1 Power Switch 2 Power input for AC 100V 240V 50 60Hz Rack mount kit assembly You can find the rack mount kit and the screws in th...

Page 9: ...sing PING request RMT Green Blinking System is being accessed remotely Ring Green On Ring enabled Slowly blinking Ring has only One link lacks one link to build the ring Fast blinking Ring work normal...

Page 10: ...specifications Cable Types and Specifications Cable Type Max Length Connector 10BASE T Cat 3 4 5 100 ohm UTP 100 m 328 ft RJ 45 100BASE TX Cat 5 100 ohm UTP UTP 100 m 328 ft RJ 45 1000BASE TX Cat 5 C...

Page 11: ...X4TX24MS switch support auto MDI MDI X operation You can use a straight through cable to connect a PC to the switch The following table below shows the 10BASE T 100BASE TX MDI and MDI X port pin outs...

Page 12: ...BI_DC Note and signs represent the polarity of the wires that make up each wire pair SFP Small Form Factor Pluggable Optical Connectors The Switch has fiber optic ports for use with with SFP connector...

Page 13: ...D Pin Male Connector Female Connector 1 Received Line Signal Detect Received by DTE Device Received Line Signal Detect Transmitted from DCE Device 2 Received Data Received by DTE Device Transmitted Da...

Page 14: ...Microsoft Internet Explorer The Web Based Management function supports Internet Explorer 5 0 or later It is based on Java Applets with an aim to reduce network bandwidth consumption enhance access sp...

Page 15: ...08 31 12 PAGE 15 INSTALLATION AND OPERATION MANUAL CWGE28FX4TX24MS TECH SUPPORT 1 888 678 9427 5 Click Enter or OK button then the main interface of the Web based management appears Login screen Main...

Page 16: ...lly qualified domain name A domain name is a text string drawn from the alphabet A Za z digits 0 9 minus sign No space characters are permitted as part of a name The first character must be an alpha c...

Page 17: ...assword required to access the web pages or log in from CLI Label Description Old Password Enter the current system password If this is incorrect the new password will not be set New Password The syst...

Page 18: ...ng you do not need to assign the IP address The network DHCP server will assign the IP address for the switch and it will be display in this column The default IP is 192 168 10 1 IP Mask Assign the su...

Page 19: ...mode operation Disabled Disable HTTPS mode operation Save Click to save changes Reset Click to undo any changes made locally and revert to previously saved values SSH Label Description Mode Indicates...

Page 20: ...the logical LLDP port Mode Select LLDP mode Rx only The switch will not send out LLDP information but LLDP information from neighbor units is analyzed Tx only The switch will drop LLDP information rec...

Page 21: ...eighbor unit Port Description Port Description is the port description advertised by the neighbor unit System Capabilites System Capabilities describes the neighbor unit s capabilities The possible ca...

Page 22: ...rs Label Description Neighbor entries were last changed at Shows the time when the entry was last deleted or added It also shows the time elapsed since last change was detected Total Neighbors Entries...

Page 23: ...d within the table Entries are removed from the table when a given port links down an LLDP shutdown frame is received or when the entry ages out TLVs Discarded Each LLDP frame can contain multiple pie...

Page 24: ...CWGE28FX4TX24MS TECH SUPPORT 1 888 678 9427 Backup Restore Configuration You can save view or load the switch configuration The configuration file is in XML format with a hierarchy of tags Firmware Up...

Page 25: ...ORT 1 888 678 9427 DHCP Server Setting The system supports DHCP server function Enable the DHCP server function and the switch system will become a DHCP server DHCP Dynamic Client List When the DHCP s...

Page 26: ...888 678 9427 DHCP Client List You can assign a specific IP address that is in the assigned dynamic IP range to the specific port When the device is connecting to the port and asks for dynamic IP addre...

Page 27: ...tion Flow Control When Auto Speed is selected for a port this section indicates the flow control capability that is advertised to the link partner When a fixed speed setting is selected that is what i...

Page 28: ...power savings mode parameters per port Disabled All power savings mechanisms disabled ActiPHY Link down power savings enabled PerfectReach Link up power savings enabled Enabled Both link up and link...

Page 29: ...raffic policing Unit is kbps and it is restricted to 1 1000 when the Traffic policing Unit is Mbps Traffic policing Unit Configure the unit of measure for the port traffic policing rate as kbps or Mbp...

Page 30: ...ss is enabled Destination MAC Address The Destination MAC Address can be used to calculate the destination port for the frame Check to enable the use of the Destination MAC Address or uncheck to disab...

Page 31: ...oup ID Normal indicates there is no aggregation Only one group ID is valid per port Port Members Each switch port is listed for each group ID Select a radio button to include a port in an aggregation...

Page 32: ...m the aggregation By default no ports belong to any aggregation group Only full duplex ports can join an aggregation and ports must be in the same speed in each group Key The key value incurred by the...

Page 33: ...he id is shown as isid aggr id and for GLAGs as aggr id Partner System ID The system ID MAC address of the aggregation partner Partner Key The Key that the partner has assigned to this aggregation ID...

Page 34: ...port could not join the aggregation group but will join if other port leaves Meanwhile it s LACP status is disabled Key The key assigned to this port Only ports with the same key can aggregate togeth...

Page 35: ...ws how many LACP frames have been sent from each port LACP Received Shows how many LACP frames have been received at each port Discarded Shows how many unknown or illegal LACP frames have been discard...

Page 36: ...imary port when this switch is Ring Master 2nd Ring Port The backup port when this switch is Ring Master Coupling Ring Mark to enable Coupling Ring Coupling Ring can be used to divide a big ring into...

Page 37: ...e failure The switch supports the function and interface for setting the switch as the ring master or not The ring master can negotiate and place command to other switches in the X Ring group If there...

Page 38: ...e The maximum age of the information transmitted by the Bridge when it is the Root Bridge Valid values are in the range 6 to 40 seconds and MaxAge must be FwdDelay 1 2 Maximum Hop Count This defines t...

Page 39: ...order to share spanning trees for MSTI s Intra region The name is at most 32 characters Configuration Revision The revision of the MSTI configuration named above This must be an integer between 0 and...

Page 40: ...ssibly change them as well Label Description MSTI The bridge instance The CIST is the default instance which is always active Priority Controls the bridge priority Lower numerical values have better p...

Page 41: ...L CWGE28FX4TX24MS TECH SUPPORT 1 888 678 9427 CIST Ports This page allows the user to inspect the current STP CIST port configurations and possibly change them as needed This page contains settings fo...

Page 42: ...the port or not Restricted Role If enabled causes the port not to be selected as Root Port for the CIST or any MSTI even if it has the best spanning tree priority vector Such a port will be selected a...

Page 43: ...n settings are stack global Label Description Port The switch port number of the corresponding STP CIST and MSTI port Path Cost Controls the path cost incurred by the port The Auto setting will set th...

Page 44: ...ge ID The Bridge ID of this Bridge instance Root ID The Bridge ID of the currently elected root bridge Root Port The switch port currently assigned the root port role Root Cost Root Path Cost For the...

Page 45: ...logical STP port CIST Role The current STP port role of the CIST port The port role can be one of the following values AlternatePort BackupPort RootPort DesignatedPort State The current STP port stat...

Page 46: ...on BPDU s received transmitted on the port STP The number of legacy STP Configuration BPDU s received transmitted on the port TCN The number of legacy Topology Change Notification BPDU s received tran...

Page 47: ...ave VLAN ID The VLAN ID for the entry MAC Address The MAC address for the entry Port Members Checkmarks indicate which ports are members of the entry Check or uncheck as needed to modify the entry Add...

Page 48: ...rtbased VLAN Setting For ingress port 1 VLAN Membership Configuration setting port 1 VID 50 2 VLAN Port 1 Configuration Disable VLAN Aware 3 VLAN Port 1 Configuration Mode specific ID 50 Portbased VLA...

Page 49: ...CH SUPPORT 1 888 678 9427 3 VLAN Port 2 Configuration Mode specific ID 50 any packet can enter egress port 802 1Q Access port Setting For ingress port 1 VLAN Membership Configuration setting port VID...

Page 50: ...CWGE28FX4TX24MS TECH SUPPORT 1 888 678 9427 802 1Q Access port Setting For egress port 1 VLAN Membership Configuration setting port VID 50 2 VLAN Port Configuration Disable VLAN Aware 3 VLAN Port Conf...

Page 51: ...P2 P6 P5 PC Station 1 PC Station 2 For ingress port 1 VLAN Membership Configuration setting port VID 11 22 33 2 VLAN Port Configuration Enable VLAN Aware 3 VLAN Port Configuration Mode specific ID 11...

Page 52: ...28FX4TX24MS TECH SUPPORT 1 888 678 9427 For egress port 1 VLAN Membership Configuration setting port VID 11 22 33 2 VLAN Port Configuration Enable VLAN Aware 3 VLAN Port Configuration Mode none Egress...

Page 53: ...UPPORT 1 888 678 9427 QinQ VLAN Setting P1 P2 P3 Q in Q mode Tag 50 tag 77 packet ingress Port 1 egress Port 2 For ingress port Port 1 1 VLAN Membership Configuration setting port 1 2 3 VID 50 2 VLAN...

Page 54: ...ATION MANUAL CWGE28FX4TX24MS TECH SUPPORT 1 888 678 9427 For egress port Port 2 1 VLAN Membership Configuration setting port VID 50 2 VLAN Port Configuration Enable Port 2 3 VLAN Aware 3 VLAN Port Con...

Page 55: ...ID to delete the entry It will be deleted during the next save Private VLAN ID Indicates the ID of this particular private VLAN MAC Address The MAC address for the entry Port Members A row of check bo...

Page 56: ...4TX24MS TECH SUPPORT 1 888 678 9427 Label Description Port Members A check box is provided for each port of a private VLAN When checked port isolation is enabled for that port When unchecked port isol...

Page 57: ...e allowed content is the ASCII characters from 33 to 126 The field only suits to SNMPv1 and SNMPv2c SNMPv3 is using USM for authentication and privacy and the community string will associated with SNM...

Page 58: ...ion Address Indicates the SNMP trap destination address Trap Authentication Failure Indicates the SNMP entity is permitted to generate authentication failure traps Possible modes are Enabled Enable SN...

Page 59: ...key is Community Label Description Delete Check to delete the entry It will be deleted during the next save Community Indicates the community access string to permit access to SNMPv3 agent The allowe...

Page 60: ...ity model that this entry should belong to Possible security models are NoAuth NoPriv No authentication and none privacy Auth NoPriv Authentication and none privacy Auth Priv Authentication and privac...

Page 61: ...Indicates the security model that this entry should belong to Possible security models are v1 Reserved for SNMPv1 v2c Reserved for SNMPv2c usm User based Security Model USM Security Name A string iden...

Page 62: ...owed content is the ASCII characters from 33 to 126 View Type Indicates the view type that this entry should belong to Possible view types are included An optional flag to indicate that this view subt...

Page 63: ...ty models are any Accepted any security model v1 v2c usm v1 Reserved for SNMPv1 v2c Reserved for SNMPv2c usm User based Security Model USM Security Level Indicates the security model that this entry s...

Page 64: ...are limited to this rate The management VLAN is configured on the IP setup page Label Description Frame Type The settings in a particular row apply to the frame type listed here unicast multicast or...

Page 65: ...ion is disabled for that port By default port isolation is disabled for all ports Default Class Configure the default QoS class for the port that is the QoS class for frames not matching any of the QC...

Page 66: ...lass of the frame The following QCE types are supported Ethernet Type The Ethernet Type field If frame is tagged this is the Ethernet Type that follows the tag header VLAN ID VLAN ID Only applicable i...

Page 67: ...ame row Low Queue There are 4 QoS queues per port with strict or weighted queuing scheduling This is the lowest priority queue Normal Queue This is the normal priority queue of the 4 QoS queues It has...

Page 68: ...al types according to different QCL policies Set up Typical Network Application Rules Set up the specific QCL for different typical network application quality control Set up ToS Precedence Mapping Se...

Page 69: ...the per VLAN IGMP Snooping IGMP Querier Enable the IGMP Querier in the VLAN The Querier will send out if no Querier received in 255 seconds after IGMP Querier Enabled Each Querier s interval is 125 s...

Page 70: ...he entry Querier Status Show the Querier status is ACTIVE or IDLE Querier Receive The number of Transmitted Querier V1 Reports Receive The number of Received V1 Reports V2 Reports Receive The number o...

Page 71: ...pply to this port The allowed values are Disabled or the values 1 through 15 The default value is Disabled Port Copy Select which port frames are copied to The allowed values are Disabled or a specifi...

Page 72: ...unit is packet per second pps configure the rate as 1 2 4 8 16 32 64 128 256 512 1K 2K 4K 8K 16K 32K 64K 128K 256K 512K or 1024K The 1 kpps is actually 1002 1 pps ACL Configuration Configure an ACE Ac...

Page 73: ...E Notice the IPv4 frames won t match the ACE with Ethernet type Action Specify the action to take with a frame that hits this ACE Permit The frame that hits this ACE is granted permission for the ACE...

Page 74: ...ork ports and Guest ports Set up Port Policies Group ports into several types according to different ACL policies Set up Typical Network Application Rules Set up the specific ACL for different typical...

Page 75: ...are RADIUS packets RADIUS packets also encapsulate EAP PDUs together with other attributes like the switch s IP address name and the supplicant s port number on the switch EAP is very flexible in that...

Page 76: ...r must be configured accordingly When authentication is complete the RADIUS server sends a success or failure indication which in turn causes the switch to open up or block traffic for that particular...

Page 77: ...ppose the client gets successfully authenticated Now assume that the client powers down his PC What should make the switch forget about the authenticated client Reauthentication will not solve this pr...

Page 78: ...globally disabled Link Down 802 1X or MAC based authentication is enabled but there is no link on the port Authorized The port is authorized This is the case when 802 1X authentication is enabled the...

Page 79: ...orarily unauthorized Reinitialize Forces a reinitialization of the port clients and thereby a re authentication immediately The port clients will transfer to the unauthorized state while the reauthent...

Page 80: ...8 678 9427 802 1X Statistics This page provides detailed IEEE 802 1X statistics for a specific switch port running port based authentication For MAC based ports it shows selected backend server RADIUS...

Page 81: ...AC based ports there are two tables containing backend server counters The left most shows a summary of all backend server counters on this port The right most shows backend server counters for the cu...

Page 82: ...h are Label Description The RADIUS Authentication Server number for which the configuration below applies Enable Enable the RADIUS Authentication Server by checking this box IP Address Enable fallback...

Page 83: ...ng values Disabled The server is disabled Not Ready The server is enabled but IP communication is not yet up and running Ready The server is enabled IP communication is up and running and the RADIUS m...

Page 84: ...LLATION AND OPERATION MANUAL CWGE28FX4TX24MS TECH SUPPORT 1 888 678 9427 The statistics map closely to those specified in RFC4668 RADIUS Authentication Client MIB Use the server select box to switch b...

Page 85: ...cator attributes received from the server Unknown Types The number of RADIUS packets that were received from the server on the authentication port and dropped as unknown Packets Dropped The number of...

Page 86: ...ady to accept access attempts Dead X seconds left Access attempts were made to the server but it did not reply within the configured timeout The server has temporarily been disabled but with get re en...

Page 87: ...packets that were received from the server on the accounting port and dropped as unknown Packets Dropped The number of RADIUS packets that were received from the server on the accounting port and drop...

Page 88: ...S module is ready to accept access attempts Dead X seconds left Access attempts were made to the server but it did not reply within the configured timeout The server has temporarily been disabled but...

Page 89: ...ble TACACS by IP Address Warning System Warning SYSLOG Setting The SYSLOG is a protocol to transmit event notification messages across networks Please refer to RFC 3164 The BSD SYSLOG Protocol System...

Page 90: ...ent Selection interface The following table describes the labels in this screen Section Description System Event System Cold Start Alert when system restart Power Status Alert when a power up or down...

Page 91: ...omatic aging MAC Table Learning If the learning mode for a given port is grayed out another module is in control of the mode so that the user cannot change it An example of such a module is the MAC Ba...

Page 92: ...er switch The MAC table is sorted first by VLAN ID and then by MAC address Label Description Delete Check to delete the entry It will be deleted during the next save VLAN ID The VLAN ID for the entry...

Page 93: ...rting point in the MAC Table Clicking the Refresh button will update the displayed table starting from that or the closest next MAC Table match In addition the two input fields will upon a Refresh but...

Page 94: ...ived and transmitted packets per port Bytes The number of received and transmitted bytes per port Errors The number of frames received in error and the number of incomplete transmissions per port Drop...

Page 95: ...his page provides detailed traffic statistics for a specific switch port Use the port select box to select which switch port details to display The displayed counters are the totals for receive and tr...

Page 96: ...on this port that have an opcode indicating a PAUSE operation Rx Drops The number of frames dropped due to lack of received buffers or egress congestion Rx CRC Alignment The number of frames received...

Page 97: ...from ports that have either source rx or destination tx mirroring enabled are mirrored to this port Disabled disables mirroring Label Description Port The logical port for the settings contained in t...

Page 98: ...level of the system log All All levels Time The time of the system log entry Message The MAC Address of this switch Auto Refresh Check this box to enable an automatic refresh of the page at regular i...

Page 99: ...age refreshes automatically and you can view the cable diagnostics results in the cable status table Note that VeriPHY is only accurate for cables of length 7 140 meters 10 and 100 Mbps ports will be...

Page 100: ...y until responses to all packets are received or until a timeout occurs PING6 server 10 10 132 20 64 bytes from 10 10 132 20 icmp_seq 0 time 0ms 64 bytes from 10 10 132 20 icmp_seq 1 time 0ms 64 bytes...

Page 101: ...figuration is retained Label Description Yes Click to reset the configuration to Factory Defaults No Click to return to the Port State page without resetting the configuration System Reboot You can re...

Page 102: ...s CLI management You can use console or telnet to management the switch by CLI CLI Management by RS 232 Serial Console 115200 8 none 1 none Before Configuring by RS 232 serial console use an DB 9 M to...

Page 103: ...INS_CWGE28FX4TX24MS_REV 08 31 12 PAGE 103 INSTALLATION AND OPERATION MANUAL CWGE28FX4TX24MS TECH SUPPORT 1 888 678 9427 Step 2 Input a name for new connection Step 3 Select to use COM port number...

Page 104: ...78 9427 Step 4 The COM port properties setting 115200 for baud rate 8 for Data bits None for Parity 1 for Stop bits and none for Flow control Step 5 The Console login screen will appear Use the keyboa...

Page 105: ...ddress 192 168 10 1 Subnet Mask 255 255 255 0 Default Gateway 192 168 10 254 User Name admin Password admin Follow the steps below to access the console via Telnet Step 1 Telnet to the IP address of t...

Page 106: ...Timezone offset Log log_id all info warning error clear Syslog Syslog ServerConfiguration ip_addr IP IP Configuration DHCP enable disable Setup ip_addr ip_mask ip_router vid Ping ip_addr_string ping_l...

Page 107: ...ort_list enable disable MaxFrame port_list max_frame Power port_list enable disable actiphy dynamic Excessive port_list discard restart Statistics port_list command VeriPHY port_list Aggr Aggr Configu...

Page 108: ...msti port_list Msti Priority msti priority Msti Map msti clear Msti Add msti vid Port Configuration port_list Port Mode port_list enable disable Port Edge port_list enable disable Port AutoEdge port_l...

Page 109: ...Authenticate port_list now Reauthentication enable disable Period reauth_period Timeout eapol_timeout Statistics port_list clear eapol radius Clients port_list all client_cnt Agetime age_time Holdtime...

Page 110: ...isable Interval interval Hold hold Delay delay Reinit reinit Info port_list Statistics port_list clear MAC MAC Configuration port_list Add mac_addr port_list vid Delete mac_addr vid Lookup mac_addr vi...

Page 111: ...class Tagprio port_list tag_prio QCL Port port_list qcl_id QCL Add qcl_id qce_id qce_id_next etype etype vid vid port udp_tcp_port dscp dscp tos tos_list tag_prio tag_prio_list class QCL Delete qcl_id...

Page 112: ...tch port port policy policy vid tag_prio dmac_type etype etype smac dmac arp sip dip smac arp_opcode arp_flags ip sip dip protocol ip_flags icmp sip dip icmp_type icmp_code ip_flags udp sip dip sport...

Page 113: ...name MD5 SHA auth_password DES priv_password User Delete index User Changekey engineid user_name auth_password priv_ password User Lookup index Group Add security_model security_name group_name Group...

Page 114: ...for VLAN Tagging IEEE 802 1w for RSTP Rapid Spanning Tree Protocol IEEE 802 1s for MSTP Multiple Spanning Tree Protocol IEEE 802 1x for Authentication IEEE 802 1AB for LLDP Link Layer Discovery Proto...

Page 115: ...mpatible MSTP RS 232 Serial Console Port RS 232 in RJ45 connector with console cable 115200bps 8 N 1 LED indicators Power indicator Green Power LED 3 R M indicator Green system operating in C Ring Mas...

Page 116: ...CH SUPPORT 1 888 678 9427 Regulatory approvals EMI FCC Part 15 CISPR EN55022 class A EMS EN61000 4 2 ESD EN61000 4 3 RS EN61000 4 4 EFT EN61000 4 5 Surge EN61000 4 6 CS EN61000 4 8 EN61000 4 11 Shock...

Page 117: ...RATE DRIVE DANBURY CT 06810 USA T 203 796 5300 F 203 796 5303 TECH SUPPORT 1 888 678 9427 INFO COMNET NET 8 TURNBERRY PARK ROAD GILDERSOME MORLEY LEEDS UK LS27 7LE T 44 0 113 307 6400 F 44 0 113 253 7...

Reviews: